{"id":"PYSEC-2026-2966","summary":"Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool","details":"Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.","aliases":["CVE-2011-1948","GHSA-p7h9-vf92-5fj5","PYSEC-2011-14","PYSEC-2026-2965"],"modified":"2026-07-13T16:43:05.701859834Z","published":"2026-07-09T16:49:32.099972Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1948"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2012:0151"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2011-1948"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=711494"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/67693"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-p7h9-vf92-5fj5"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2011-14.yaml"},{"type":"WEB","url":"http://plone.org/products/plone/security/advisories/CVE-2011-1948"},{"type":"PACKAGE","url":"https://pypi.org/project/products-passwordresettool"}],"affected":[{"package":{"name":"products-passwordresettool","ecosystem":"PyPI","purl":"pkg:pypi/products-passwordresettool"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.6"}]}],"versions":["1.1","1.2","1.3","1.4","2.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0a1","2.0b1","2.0b2","2.0b3","2.0b4","2.0b5","2.0b6","2.0b7"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/products-passwordresettool/PYSEC-2026-2966.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}